Search CVE reports
71 – 80 of 43490 results
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the same memory pointer causing a...
1 affected package
389-ds-base
| Package | 20.04 LTS |
|---|---|
| 389-ds-base | Needs evaluation |
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination...
1 affected package
unbound
| Package | 20.04 LTS |
|---|---|
| unbound | Needs evaluation |
A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming...
1 affected package
sbc
| Package | 20.04 LTS |
|---|---|
| sbc | Needs evaluation |
[Heap-Based Buffer Overflow in KMREQ Handling]
1 affected package
srt
| Package | 20.04 LTS |
|---|---|
| srt | Needs evaluation |
[Encryption State Machine Downgrade]
1 affected package
srt
| Package | 20.04 LTS |
|---|---|
| srt | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel...
1 affected package
netty
| Package | 20.04 LTS |
|---|---|
| netty | Needs evaluation |
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to...
1 affected package
libarchive
| Package | 20.04 LTS |
|---|---|
| libarchive | Needs evaluation |